CVE-2020-24394

Severity
7.1HIGH
EPSS
0.1%
top 83.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 19
Latest updateMay 24

Description

In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages5 packages

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fvv9-qhmx-c8wm: In the Linux kernel before 52022-05-24
CVEList
CVE-2020-24394: In the Linux kernel before 52020-08-19
OSV
CVE-2020-24394: In the Linux kernel before 52020-08-19

📋Vendor Advisories

6
Ubuntu
Linux kernel vulnerabilities2020-09-03
Ubuntu
Linux kernel vulnerabilities2020-09-03
Ubuntu
linux kernel vulnerabilities2020-08-23
Microsoft
In the Linux kernel before 5.7.8 fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support aka CID-22cf8419f131. This occurs becau2020-08-11
Red Hat
kernel: umask not applied on filesystem without ACL support2020-06-05

💬Community

1
Bugzilla
CVE-2020-24394 kernel: umask not applied on filesystem without ACL support2020-08-17